nerdexam
Amazon

DOP-C02 · Question #242

A company needs to adopt a multi-account strategy to deploy its applications and the associated CI/CD infrastructure. The company has created an organization in AWS Organizations that has all…

The correct answer is A. Create an AWS Control Tower Account Factory Customization (AFC) blueprint that uses the. To provision new accounts for a multi-environment application with an initial baseline and AWS Control Tower guardrails with least operational overhead, use AWS Control Tower Account Factory Customization (AFC) to define and apply the custom baseline during account creation.

Submitted by parkjh· Mar 6, 2026Security & Compliance

Question

A company needs to adopt a multi-account strategy to deploy its applications and the associated CI/CD infrastructure. The company has created an organization in AWS Organizations that has all features enabled. The company has configured AWS Control Tower and has set up a landing zone. The company needs to use AWS Control Tower controls (guardrails) in all AWS accounts in the organization. The company must create the accounts for a multi-environment application and must ensure that all accounts are configured to an initial baseline. Which solution will meet these requirements with the LEAST operational overhead?

Options

  • ACreate an AWS Control Tower Account Factory Customization (AFC) blueprint that uses the
  • BUse AWS Control Tower Account Factory to provision a dedicated AWS account for each
  • CUse Organizations to provision a multi-environment AWS account and a CI/CD account. In the
  • DUse Organizations to provision a dedicated AWS account for each environment, an audit account,

How the community answered

(42 responses)
  • A
    81% (34)
  • B
    5% (2)
  • C
    2% (1)
  • D
    12% (5)

Why each option

To provision new accounts for a multi-environment application with an initial baseline and AWS Control Tower guardrails with least operational overhead, use AWS Control Tower Account Factory Customization (AFC) to define and apply the custom baseline during account creation.

ACreate an AWS Control Tower Account Factory Customization (AFC) blueprint that uses theCorrect

AWS Control Tower Account Factory Customization (AFC) allows extending the default Control Tower account baseline with custom configurations through blueprints, ensuring that all newly provisioned accounts for different environments automatically receive both Control Tower guardrails and a company-specific initial baseline with minimal operational overhead.

BUse AWS Control Tower Account Factory to provision a dedicated AWS account for each

Using only the AWS Control Tower Account Factory provisions accounts with the default Control Tower baseline but does not include the ability to apply a *custom* initial baseline, thus requiring additional manual steps or separate automation.

CUse Organizations to provision a multi-environment AWS account and a CI/CD account. In the

Provisioning accounts directly through AWS Organizations bypasses the AWS Control Tower Account Factory, meaning these accounts would not automatically be enrolled in the Control Tower landing zone or receive its guardrails and baseline, leading to higher operational overhead for compliance.

DUse Organizations to provision a dedicated AWS account for each environment, an audit account,

Similar to option C, provisioning accounts directly via AWS Organizations prevents the automatic application of AWS Control Tower guardrails and the baseline, increasing the manual effort needed to ensure compliance and initial configuration.

Concept tested: AWS Control Tower Account Factory Customization for multi-account strategy

Source: https://docs.aws.amazon.com/controltower/latest/userguide/account-factory-customizations.html

Topics

#AWS Control Tower#Multi-account strategy#Account Factory Customization#Guardrails

Community Discussion

No community discussion yet for this question.

Full DOP-C02 Practice